This Privacy Policy explains how winnox collects, uses, stores, and protects the personal data of players and website visitors. We are committed to handling your information responsibly and in compliance with applicable data protection law.
Six principles that define how winnox handles your personal information.
Your personal data is stored on encrypted servers protected by industry-standard 256-bit TLS. We apply strict access controls — only personnel who need your data to perform their role can access it, and all access is logged and audited.
winnox does not sell, rent, or trade your personal data to third parties for commercial purposes. Your information is used solely to operate your Account, process payments, comply with legal obligations, and improve the Platform.
Under applicable data protection law, you have the right to access, correct, or request deletion of your personal data. You may also object to certain processing activities. winnox will respond to all valid data rights requests within 30 days.
We collect only the data that is necessary to operate the Platform, verify your identity, process payments, and meet our regulatory obligations. We do not collect data for its own sake or retain it beyond the period required by law or operational need.
winnox processes personal data in accordance with our international gaming authority licence requirements and Malaysian personal data protection principles. KYC documents are handled under strict confidentiality protocols and are never shared with third parties except where legally required.
In the unlikely event of a data breach that affects your personal data, winnox will notify affected players promptly in accordance with applicable notification obligations. We maintain an incident response plan specifically for data security events.
This Privacy Policy applies to the winnox online casino and sportsbook platform, accessible at winnox.app ("Platform"), operated by the winnox entity licensed under an international gaming authority ("winnox", "we", "us", "our").
winnox is the data controller in respect of personal data collected from players and website visitors through the Platform. If you have any questions about how winnox handles your personal data, please contact us using the details at Section 14 of this Policy.
winnox collects personal data through a number of channels when you interact with the Platform. The categories of personal data we collect include:
2.1 Registration Data. When you create a winnox Account, we collect your full name, date of birth, email address, chosen username, and your registered Malaysian mobile number. This information is required to create and manage your Account.
2.2 Identity Verification (KYC) Data. To comply with our licence conditions and anti-money laundering obligations, we collect identity documents — typically a Malaysian MyKad or passport — along with selfie verification images and, where required, proof of address or source of funds documentation.
2.3 Financial Data. We collect details of your payment methods to process deposits and withdrawals. This includes your Touch n Go eWallet account reference, Boost account reference, FPX bank account details (bank name, masked account number), and transaction history on the Platform. winnox does not store full payment card numbers where card payments are used; card data is handled by our PCI-DSS compliant payment processor.
2.4 Gaming Activity Data. We maintain records of your gaming activity on the Platform, including game sessions, bets placed, game outcomes, bonus usage, and session duration. This data is used for account management, dispute resolution, responsible gaming monitoring, and regulatory compliance.
2.5 Device and Technical Data. When you access the Platform, we automatically collect your IP address, device type and identifier, browser type and version, operating system, and session timestamps. This data is used for security monitoring, fraud detection, and Platform performance optimisation.
2.6 Communications Data. We retain records of your communications with winnox support, including Live Chat transcripts and email correspondence. These records are maintained for quality assurance, dispute resolution, and regulatory compliance purposes.
2.7 Responsible Gaming Data. Where you voluntarily use winnox's responsible gaming tools (deposit limits, loss limits, self-exclusion), we record the settings you configure and the dates on which they were applied. This data is used solely to enforce the controls you have chosen and to protect your interests as a player.
winnox uses your personal data for the following purposes:
winnox processes your personal data under the following legal bases:
winnox does not sell, rent, or trade your personal data to third parties. We share data only in the following circumstances:
5.1 Service Providers. We share data with trusted third-party service providers who assist in the operation of the Platform, including payment processors, identity verification providers, game software suppliers, cloud hosting providers, and customer support platform providers. All service providers are bound by data processing agreements requiring them to protect your data and use it only for the specific purpose for which it was shared.
5.2 Regulatory Authorities. We may be required to disclose personal data to our licensing authority, financial intelligence units, law enforcement agencies, or other regulatory bodies where required by law or where we have a good-faith belief that disclosure is necessary to comply with a legal obligation or protect the rights of winnox or third parties.
5.3 Responsible Gaming Bodies. Where a Player is placed on a self-exclusion register administered by a gaming regulatory body, winnox may be required to share limited identification data with that registry to enforce exclusion across multiple operators.
5.4 Business Transfers. In the event of a merger, acquisition, or sale of all or part of winnox's business, your personal data may be transferred to the acquiring entity, subject to the same level of data protection as set out in this Policy. You will be notified of any such transfer.
Identity documents submitted for KYC purposes (MyKad, passport, proof of address, selfie images) are treated with the highest level of confidentiality. This data is:
If your KYC application is rejected, the documents you submitted will be deleted within 30 days of the rejection notification, unless retention is required by applicable law.
The winnox Platform uses cookies and similar tracking technologies to deliver and improve the Platform experience. The types of cookies we use include:
winnox does not use third-party advertising cookies or cross-site tracking technologies. You may manage cookie preferences through your browser settings; however, disabling essential cookies will prevent you from logging in to the Platform.
winnox retains your personal data for the periods set out below, after which data is securely deleted or anonymised:
Subject to applicable law and our regulatory obligations, you have the following rights in respect of your personal data held by winnox:
To exercise any of these rights, please contact winnox via Live Chat or by email at: [email protected]. We will respond within 30 days of receiving your request. We may need to verify your identity before processing certain requests.
winnox implements a range of technical and organisational security measures to protect your personal data from unauthorised access, disclosure, alteration, or destruction. These measures include:
While we take all reasonable steps to protect your data, no internet transmission is 100% secure. You are responsible for maintaining the security of your own Account credentials and for notifying us immediately if you suspect unauthorised access.
The operation of the winnox Platform may involve the transfer of your personal data to servers or service providers located outside Malaysia. Where such transfers occur, winnox ensures that appropriate safeguards are in place to protect your data at a level equivalent to the protections provided under applicable Malaysian personal data protection principles. These safeguards include contractual data processing agreements with all data processors incorporating standard data protection clauses.
The winnox Platform is strictly intended for adults aged 21 and above. We do not knowingly collect personal data from individuals under 21 years of age. If we become aware that a player under 21 has registered an Account, we will immediately close the Account, return any deposited funds to the payment source, and delete all associated personal data. If you believe a person under 21 has opened a winnox Account, please contact us immediately via Live Chat or at [email protected].
winnox reserves the right to update this Privacy Policy from time to time to reflect changes in our data practices, regulatory requirements, or operational needs. When we make material changes, we will notify you via a notification within the Platform or by email to your registered address at least 14 days before the changes take effect. The updated Policy will display a revised "Last Updated" date at the top of this page. Your continued use of the Platform after the effective date of an updated Policy constitutes acceptance of the revised terms.
If you have questions, concerns, or requests relating to this Privacy Policy or the way winnox handles your personal data, please contact our Data Protection team via:
We aim to acknowledge all privacy-related enquiries within 48 hours and to provide a full response within 30 days.
Ready to enjoy a secure, licensed, and fair casino experience? Explore over 1,000 games and a full sportsbook — with the confidence that your data and winnings are protected.
Explore winnox Casino